BIOC Informational

Modification of the Winlogon\Shell Registry key

Malware may modify the Winlogon\Shell Registry value to load itself instead of explorer.exe, which is the default system shell.

Module:
Platform Analytics
Agent event type:
Registry
Category:
Persistence
Status:
Enabled
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Boot or Logon Autostart Execution: Winlogon Helper DLL (T1547.004)
Indicator:

Registry registry data != explorer.exe AND registry key name = *\software\microsoft\windows nt\currentversion\winlogon* AND registry value name = shell AND action type = set_registry_value Host host os = windows

Preventable: yes